MCP Broker
API provider
Connection to a remote MCP server whose users log in through Nectry’s OAuth broker, which holds a client registered with the server’s authorization server in advance. Endpoints declared on this connection are tool calls, exactly as for the MCP provider. Use it when that authorization server does not register clients dynamically (HubSpot’s MCP Auth Apps, say); use MCP OAuth when it does.
- API category:
Generic - Reaches:
HubSpot, whichever the api’sissuersetting names, so an api on this provider counts as that kind of connection wherever one is asked for. - Needs login: Yes, three-legged: each end-user must complete an OAuth-style login flow
Configuration parameters
Required
description: string; required
Human-readable label for this provider (shown on the login button).
Optional
issuer: string; optional; default$NECTRY_BROKER_ORIGIN/google
The broker’s issuer URL: its origin,/oauth/, and the upstream provider’s name. Every endpoint is derived from it, as is the service this api counts as reaching, so a tool asking for a Google connection takes an api whose issuer ends in/googleand no other. Leave it at the default, which reads the origin out of the app’s environment and so follows the app from one deployment to the next; a literal URL (e.g.http://localhost:8081/oauth/google) ties the app to one deployment.scopes: string; optional; default ``
Extra upstream scopes to ask for at login, space-separated (e.g.https://www.googleapis.com/auth/gmail.readonly). An escape hatch for a permission no declared endpoint stands for: an endpoint’s ownscopes:list is the normal way to ask, and the only one the app’s scope manifest records, so a scope written here is requested of the user and reported as required by nothing. Identity scopes are always requested and need not be listed. The broker refuses any scope outside its own allowlist, so a rejected one fails at login.client_secret: string; optional; default$NECTRY_BROKER_CLIENT_SECRET
The secret derived from this build’s client id,base64url(HMAC-SHA256(master key, "client:" + client id)). Leave it at the default, which is that value as the deployment hands it to the build; a literal secret both leaks and pins the app to the master key it was derived under, and gives its two builds the same credentials.
What components can use this API
Concepts:
Ingredients:
Call API endpoint(informIngredients)Call API endpoint(inrowActionsIngredients)Call list API endpoint(inrowActionsIngredients)Load list column from API endpoint(inrowActionsIngredients)Paginated API GET(inrowActionsIngredients)Render as file link(incustomShowIngredientsList)Render as image(incustomShowIngredientsList)Set via API call(insetterIngredientsList)